Rey (vulpish aspect) is a user on vulpine.club. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.
Rey (vulpish aspect) @rey

(Noodling hat: ON)

So, we're getting a lot of new instances. Like, nearly 90 new ones in the last 24 hours. This is great.

Here's my concern: $5 and I can get a new instance up and going in about an hour. Do it enough and I bet I can get it down to 5 minutes, including domain registration. This makes a blocklist impractical for protecting against hostile actors with money, time, and skills.

What we may need, more than a global blacklist, is a global whitelist.

1/

@rey I really hope this doesn't become necessary :|

@rey some kind of greylisting, or requiring a follower on a trusted instance or something, might work well enough?
disincentivising new instances is bad for the health of the ecosystem imo

@edef those might indeed work out pretty well, and are probably worth trying.

the trick is to make the process of federation easy enough that new instances can join and flourish, but not completely automatic (as it is now). i'd think something along the lines of letsencrypt would be the level of friction i'd want to see?

global whitelist idea 2/ Show more

global whitelist idea 3/ Show more

global whitelist idea 4/end Show more

P.S. the above thread is a thought experiment, not a fully-baked proposal. The idea popped into my head, and so I fleshed it out a bit and shared it with y'all for discussion.

You have my permission to condemn this global whitelist idea as a pile of rubbish. I may actually agree with you.

@rey i kinda dig this idea, or something like it. and no one could stop someone from federating with groups outside the whitelist, but if you're on the whitelist you agree to some base-level good behavior TOS

@rey and it'd be cool if the basic mastodon software synced with it so admins could switch between "unfiltered federation" vs. "whitelisted instances"

@rey i'd even settle for a way to set up mastodon to accept a blacklist or whitelist, and let admins share those lists via importable files. maybe that would soothe the folks worried about centralization

@rey The big problem I see with a central whitelist is you have to appeal to an authority, which is what some have come here to get away from.
I could see a PGP-style WoT concept working. Instance admins get to know and vouch for each other. Each admin can then determine how deep in the WoT to allow, ie: 1 (only instances I know), 2 (friend-of-a-friend) on out to infinity.

@rey We can think of this as a lesson from the evolution of our own immune system: It rejects foreign bodies by default because they're statistically far more likely to be pathogens or toxins than not. Homeostasis is just far too fragile to manage otherwise.

@rey awoo.space is working off of a federation whitelist actually, hand-built by the mods. I have concerns but there's some definite upsides.

@starkatt yep! it works nicely, but it absolutely will not scale due to administrative overhead. and this is fine! the fediverse is a great laboratory with all sorts of techno-social experimentation and meta-pondering and i love it

@rey I've got it down to five (parallelizable) minutes: github.com/kstrauser/freeradic

Register twenty domains, run that repo against all the new instances simultaneously, and voila.

@tek we live in truly wonderful times. i don't even have to develop my own proofs-of-concept. =^.^=

@Almafeta i think it's inevitable at some point, tbh, which is why i'm thinking about it now :>

@Almafeta @rey Yeah, I would hope it not be one global but more subscription-based like Block Together or similar.